CVE-2026-105400: ImageMagick before 7.1.2-31 Unclosed File Pointer via Magick Script
ImageMagick before 7.1.2-31 contains a resource leak vulnerability that allows attackers to leave file pointers open by supplying a crafted magick script. Attackers can process malicious magick scripts to leak file descriptors, potentially exhausting resources and causing denial of service.
Affected Software
Event History
Frequently Asked Questions
What must an attacker be able to do to exploit this issue?
An attacker must be able to cause ImageMagick to process a crafted magick script. No authentication or user interaction is required according to the supplied vector.
What is the practical impact of successful exploitation?
Processing malicious magick scripts can leave file pointers open, leaking file descriptors over time. This can exhaust available resources and result in denial of service; no confidentiality or integrity impact is identified.
Which versions need remediation?
ImageMagick versions before 7.1.2-31 are affected. Updating to 7.1.2-31 or later addresses the affected version range described.